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APPENDIX OF CLAIMS 

1. A data carrier having a semiconductor chip (5) with at least one memory 
containing an operating program which is able to execute at least one operation (h), the 
execution of the operation (h) requiring input data (x) and the execution of the operation 
(h) generating output data (y), characterized in that 

the operation (h) is disguised before its execution, 

the disguised operation (h R1 ) is executed with disguised input data (x 0 

RJ, and 

the disguising of the operation (h) and the input data (x) is coordinated 
such that the execution of the disguised operation (h R1 ) with disguised input data (x ® 
RJ yields output data (y) identical with the output data (y) determined upon execution 
of the undisguised operation (h) with undisguised input data (x). 

2. A data carrier according to claim 1 , characterized in that at least one random 
number (RJ enters into the determination of the disguised operation (h R1 ) and the 

disguised input data (x (8> R^. 

3(amended). A data carrier according to claim 1, characterized in that the 
determination of the disguised operation (h R1 ) and the disguised input data (x ® is 
effected with the aid of EXOR operations. 

4(amended). A data carrier according to claim 1, characterized in that the 
disguised operation (h R1 ) is permanently stored in the data carrier in advance. 

5. A data carrier according to claim 4, characterized in that at least two 
disguised operations (h R1 , h R1 .) are permanently stored in the data carrier in advance 

-1- 
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and one of the stored disguised operations (h R1 , h Rr ) is selected randomly when a 
disguised operation is to be executed. 

6(amended). A data carrier according to claim 1, characterized in that the 
disguised operation (h R1 ) is recalculated before its execution and the at least one 
random number (RJ is redetermined for said calculation. 

7 (amended). A data carrier according to claim 1, characterized in that the 
operation (h) is realized by a table stored in the data carrier which establishes an 
association between the input data (x) and the output data (y). 

8. A data carrier according to claim 7, characterized in that the disguising of the 
input data (x) contained in the table is effected by combination with the at least one 
random number (RJ. 

9. A data carrier having a semiconductor chip (5) with at least one memory 
containing an operating program which is able to execute at least one operation (h), the 
execution of the operation (h) requiring input data (x) and the execution of the operation 
(h) generating output data (y), characterized in that 

the operation (h) is disguised before its execution, 

the disguised operation (h R1 ) is executed with disguised input data (x ® 

the disguising of the operation (h) and the input data (x) is coordinated 
such that the execution of the disguised operation (h R1R2 ) with disguised input data (x 

® RJ yields output data (y ® R^ which are disguised relative to the output data (y) 

determined upon execution of the undisguised operation (h)w\\h undisguised input data 
(x), and 
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the undisguised output data (y) can be determined from the disguised 
output data (y ® with the aid of data (RJ used for disguising the operation (h). 

1 0. A data carrier according to claim 9, characterized in that at least one random 

number (R,) enters into the determination of the disguised input data (x ® RJ and at 

least two random numbers (R p RJ enter into the determination of the disguised 
operations (h R1R2 ). 

11 (amended). A data carrier according to claim 9, characterized in that the 
determination of the disguised operation (h R1R2 ) and the disguised input data (x ® RJ 
is effected with the aid of EXOR operations. 

12(amended). A data carrier according to claim 9, characterized in that the 
disguised operation (h R1R2 ) is permanently stored in the data carrier in advance. 

13. A data carrier according to claim 12, characterized in that at least two 
disguised operations (h R1R2 , h RrR2 .) are permanently stored in the data carrier in 
advance and one of the stored disguised operations (h R1R2 , h RVR2 .) is selected randomly 
when a disguised operation is to be executed. 

14. A data carrier according to claim 13, characterized in that the random 
numbers (R v RJ for determining the first disguised operation (h R1R2 ) are inverse to the 
random numbers (R/, R 2 ') for determining the second disguised operation (h RVR2 ,)w\th 
respect to the combination used for determining the disguised operations (h R1R2 , h RrR2 ). 

15(amended). A data carrier according to claim 9, characterized in that the 
disguised operation (h R1R2 ) is recalculated before its execution and the random numbers 
(R 1t R^ are redetermined for said calculation. 
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16(amended). A data carrier according to claim 9, characterized in that the 
operation (h) is realized by a table stored in the data carrier which establishes an 
association between the input data (x) and the output data (y). 

17. A data carrier according to claim 16, characterized in that the disguising of 
the input data (x) contained in the table is effected by combination with the at least one 
random number (RJ and the disguising of the output data (y) contained in the table is 
effected by combination with the at least one further random number (RJ. 

18(amended). A data carrier according to claim 1, characterized in that the 
operation (h) is a nonlinear operation with respect to the combination used for 
disguising the operation (h). 
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A data carrier having a semiconductor chip (5) with at least one memory con- 
taining an operating program which is able to execute at least one operation 
(/?), the execution of the operation (h) requiring input data (x) and the execution 
of the operation (h) generating output data (y), characterized in that 
the operation (h) is disguised before its execution, 
the disguised operation (h R \) is executed with disguised input data 
(x ® R } \ and 

the disguising of the operation (h) and the input data (x) is coordinated 
such that the execution of the disguised operation (h R \) with disguised in- 
put data (x ® R\) yields output data (y) identical with the output data (y) 
determined upon execution of the undisguised operation (h) with undis- 
guised input data (x). 
A data carrier according to claim 1, characterized in that at least one random 
number (R { ) enters into the determination of the disguised operation (h R {) and 
the disguised input data (x ® t 

A data carrier according to/either of^^above claims] characterized in that the 
determination of the disguised operation (h m ) and the disguised input data 
(x ® R x ) is effected with the aid of EXOR operations. 



A data carrier according tojany oftHeabove claim^ characterized in that the 

disguised operation (h R \) is permanently stored in the data carrier in advance, 
A data carrier according to claim 4, characterized in that at least two disguised 
operations (h RU h RV ) are permanently stored in the data carrier in advance and 
one of the stored disguised operations (h RU h RV ) is selected randomly when a 
disguised operation is to be executed. * 

A data carrier according tojany of claims 1 to3J characterized in that the dis- 
guised operation (h Ri ) is recalculated before its execution and the at least one 
random number (R } ) is redetermined for said calculation. 





-8- 



7. A data carrier according to^iv- o^l^above claimj characterized in that the 
operation (h) is realized by a table stored in the data carrier which establishes 
an association between the input data (x) and the output data (y). 

8. A data carrier according to claim 7, characterized in that the disguising of the 
input data (x) contained in the table is effected by combination with the at least 
one random number (R x ). 

9. A data carrier having a semiconductor chip (5) with at least one memory con- 
taining an operating program which is able to execute at least one operation 
(/?), the execution of the operation (h) requiring input data (x) and the execution 
of the operation (h) generating output data (y) ? characterized in that 

the operation (h) is disguised before its execution, 

the disguised operation (h m ) is executed with disguised input data 

the disguising of the operation (h) and the input data (jc) is coordinated 
such that the execution of the disguised operation (h^ R2 ) with disguised 
input data (x ® R\) yields output data (y ® R 2 ) which are disguised rela- 
tive to the output data (y) determined upon execution of the undisguised 
operation (h) with undisguised input data (x), and 

the undisguised output data (y) can be determined from the disguised out- 
put data (y ® R2) with the aid of data (R 2 ) used for disguising the opera- 
tion (h). 

10. A data carrier according to claim 9, characterized in that at least one random 
number (i?i) enters into the determination of the disguised input data (x ® R\) 
and at least two random numbers (R u R2) enter into the determination of the 
disguised operations (h R]R2 ). . n 

11. A data earner according to] either of claims 9 and ly, characterized in that the 
determination of the disguised operation (hRiRz) and the disguised input data 
(x ® R\) is effected with the aid of EXOR operations. 

12. A data earner according to /any of claims 9 to llf characterized m that the dis- 
guised operation (h R i R2 ) is permanently stored in the data carrier in advance. 
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13. A data carrier according to claim 12, characterized in that at least two dis- 
guised operations {h mR2 , h RVR2 :) are permanently stored in the data carrier in 
advance and one of the stored disguised operations (h RXR2 , h RVR2 ) is selected 
randomly when a disguised operation is to be executed. 

14. A data carrier according to claim 13, characterized in that the random numbers 
(Ru Ri) for determining the first disguised operation (h R \ R2 ) are inverse to the 
random numbers (R\\ R 2 ) for determining the second disguised operation 
(h RVR2 ) with respect to the combination used for determining the disguised 
operations (h Rva , h RVR2 ). \ ^ 

15. A data carrier according toimy oTcmmi^ to JjJ characterized in that the dis- 
guised operation (Afci/e) is recalculated before its execution and the random 
numbers (R u Ri) are redetermined for said calculation. 



16. A data carrier according to/any of claims 9 to 15f characterized in that the op- 
eration (h) is realized by a table stored in the data carrier which establishes an 
association between the input data (x) and the output data (y). 

17. A data carrier according to claim 16, characterized in that the disguising of the 
input data (x) contained in the table is effected by combination with the at least 
one random number (R\) and the disguising of the output data (y) contained in 
the table is effected by combination with the at least one further random num- 



operation (/?) is a nonlinear operation with respect to the combination used for 
disguising the operation (h). 




ber (R 2 ). 




18. A data carrier according to jany of the above 



characterized in that the 



09/7636 
528 Rec'd PCT/KTO 5 5 &'.A3 

Access-protected data carrier 



This invention relates to a data carrier having a semiconductor chip in which 
secret data are stored. The invention relates in particular to a smart card. 

Data carriers containing chips are used in a great number of different applica- 
tions, for example for performing monetary transactions, paying for goods or ser- 
vices, or as an identification means for access or admission controls. In all said ap- 
plications the data carrier chip normally processes secret data which must be pro- 
tected from access by unauthorized third parties. Said protection is ensured by, 
among other things, giving the inner structures of the chip very small dimensions so 
that it is very difficult to access said structures with the aim of spying out data proc- 
essed in said structures. In order to impede access further, one can embed the chip in 
a very firmly adhering compound whose forcible removal destroys the semiconduc- 
tor plate or at least the secret data stored therein. It is also possible to provide the 
semiconductor plate during its production with a protective layer which cannot be 
removed without destroying the semiconductor plate. 

With corresponding technical equipment, which is extremely expensive but 
nevertheless fundamentally available, an attacker could possibly succeed in expos- 
ing and exaniining the inner structure of the chip. Exposure could be effected for 
example by special etching methods or a suitable grinding process. The thus exposed 
structures of the chip, such as conductive paths, could be contacted with micro- 
probes or examined by other methods to determine the signal patterns in said struc- 
tures. Subsequently, one could attempt to determine from the detected signals secret 
data of the data carrier, such as secret keys, in order to use them for purposes of ma- 
nipulation. One could likewise attempt to selectively influence the signal patterns in 
the exposed structures via the microprobes. 

The invention is based on the problem of protecting secret data present in the 
chip of a data carrier from unauthorized access. 

This problem is solved by the feature combinations of claims 1 and 9. 

The inventive solution does not aim, like the prior art, at preventing exposure 
of the internal structures of the chip and the mounting of microprobes. Instead 




measures are taken to make it difficult for a potential attacker to infer secret infor- 
mation from any signal patterns intercepted. Said measures consist according to the 
invention in manipulating security-relevant operations so that the secret data used in 
performing said security-relevant operations cannot be determined without including 
further secret information. For this purpose the security-relevant operations are dis- 
guised or falsified with the aid of suitable functions before execution. In order to 
impede or even prevent in particular a statistical evaluation in case of multiple exe- 
cution of the security-relevant operations, a random component enters into the dis- 
guising function. As a result, an attacker cannot determine the secret data from any 
data streams intercepted. 

The security-relevant operation will be represented in the following by func- 
tion h mapping input data x on output dataj, i.e. y = h(x). To prevent secret input 
data x from being spied out the invention provides for disguised function h RiR2 to be 
determined, so that the following holds: 

y®R 2 =-h mR2 (x®R l ). 

The security-relevant operation is now performed by means of disguised func- 
tion hgxia whose input data are not authentic secret data x but disguised secret data 
x ® Rx generated by combining authentic secret data x with random number R\. 
Without knowledge of random number R\ one cannot determine authentic secret 
data x from disguised secret data x ® R\, As a result of applying disguised function 
buna to disguised secret data x <S> R x one obtains disguised output data y ® R 2 . From 
disguised output data>> ® R 2 one can determine output data y by suitable combina- 
tion. Before each new execution of the security-relevant ftmction one can preset new 
random numbers R\ and R 2 from which new disguised function h RXR2 is determined 
in each case. Alternatively, a plurality of disguised functions h RiR2 can be perma- 
nently stored, one of which is selected randomly before execution of the security- 
relevant operation. It is especially advantageous to use two functions hiam and 
h RVR2 \ random numbers R\ ' and R 2 ' being the inverse values of random numbers Ri 
and i?2 with respect to the type of combination selected for disguising. In a further 
variant, random numbers R\ and R 2 can also be identical. In particular, random num- 



bers R\ and R 2 can be selected statistically independently so that there is no correla- 
tion between input and output data which can be used for an attack. 

If further operations are executed before or after security-relevant operation h 
in question here, random numbers R\ and R 2 can also be used for disguising the data 
processed with the further operations. 

The inventive solution can be used especially advantageously for security- 
relevant operations containing nonlinear functions. With nonlinear functions one 
cannot apply known protective measures based on disguising the secret data before 
execution of the functions. Known protective measures presuppose that the functions 
are linear with respect to the disguising operations so that disguising can be undone 
after execution of the functions. In the inventive solution, however, not only the se- 
cret data are falsified or disguised but also the security-relevant operations process- 
ing the secret data. The disguising of the secret data and the security-relevant opera- 
tions is coordinated such that the authentic secret data can be derived from the dis- 
guised secret data after execution of the security-relevant operations. Coordination 
between disguising of the secret data and the security-relevant operations can be re- 
alized especially simply if the security-relevant operations are realized in the form of 
tables, so-called lookup tables. In the stated tables each input value x has output 
value y associated therewith. The functions realized by the tables are executed by 
looking up output values y belonging to particular input values x. 

The invention will be explained below with reference to the embodiments 
shown in the figures, in which: 

Fig. 1 shows a smart card in a top view, 

Fig. 2 shows a greatly enlarged detail of the chip of the smart card shown in 
Fig. 1 in a top view, 

Figs. 3a, 3b, 3c and 3d show representations of lookup tables. 

Fig. 1 shows smart card 1 as an example of the data carrier. Smart card 1 is 
composed of card body 2 and chip module 3 set in a specially provided gap in card 
body 2. Essential components of chip module 3 are contact surfaces 4 for producing 
an electric connection with an external device, and chip 5 electrically connected with 
contact surfaces 4. As an alternative or in addition to contact surfaces 4, a coil not 



shown in Fig. 1 or other transfer means can be present for producing a communica- 
tion link between chip 5 and an external device. 

Fig. 2 shows a greatly enlarged detail of chip 5 from Fig. 1 in a top view. The 
special feature of Fig. 2 is that it shows the active surface of chip 5, i.e. it does not 
show all layers generally protecting the active layer of chip 5. In order to obtain in- 
formation about the signal patterns in the interior of the chip one can for example 
contact exposed structures 6 with microprobes. Microprobes are very thin needles 
which are brought in electric contact with exposed structures 6, for example conduc- 
tive paths, by means of a precision positioning device. The signal patterns picked up 
by the microprobes are processed with suitable measuring and evaluation devices 
with the aim of inferring secret data of the chip. 

The invention makes it very difficult or even impossible for an attacker to gain 
access to in particular secret data of the chip even if he has managed to remove the 
protective layer of chip 5 without destroying the circuit and to contact exposed struc- 
tures 6 of chip 5 with microprobes or intercept them in some other way. The inven- 
tion is of course also effective if an attacker gains access to the signal patterns of 
chip 5 in another way. 

Figures 3a 5 3b, 3c and 3d show simple examples of lookup tables in which the 
input and output data each have a length of 2 bits. All table values are represented as 
binary data. The first line states input data x, and the second line output data asso- 
ciated therewith in the particular column. 

Figure 3 a shows a lookup table for undisguised function h. Figure 3 a indicates 
that input value x = 00 has output value h (x) = 01 associated therewith, input value 
01 output value 1 1, input value 10 output value 10, and input value 1 1 output value 
00. The lookup table according to Figure 3a represents nonlinear function h which is 
to be executed within the framework of a security-relevant operation. According to 
the invention, however, one does not use the lookup table shown in Figure 3 a itself 
in executing the security-relevant operation, but derives a disguised lookup table 
from said lookup table according to Figures 3b, 3c and 3d. 

Figure 3b shows an intermediate step in determining the disguised lookup ta- 
ble. The lookup table according to Figure 3b was generated from the lookup table 



according to Figure 3 a by EXORing each value of the first line of the table from 
Figure 3 a with random number R\ = 1 1. Thus, EXORing the value 00 of the first line 
and first column of the table from Figure 3 a with the number 1 1 yields the value 1 1, 
which is now the element of the first line and first column of the table of Figure 3b. 
The remaining values of the first line of the table shown in Figure 3b are determined 
accordingly from the values of the first line of the table shown in Figure 3 a and ran- 
dom number J?i = 11. The table shown in Figure 3b could already be used as a dis- 
guised lookup table for processing secret data likewise disguised with random num- 
ber i?i = 11. The result would be the plaintext values to be read in line 2 of the table 
from Figure 3b. 

One usually arranges the individual columns of a lookup table according to as- 
cending input data x, A table determined by accordingly sorting the table in Figure 
3b is shown in Figure 3c. 

If the table according to Figure 3 c is to be disguised further or yield as output 
values likewise disguised values rather than plaintext values, one applies a further 
EXOR operation with further random number i? 2 . 

Figure 3d shows the result of applying said further EXOR operation. In said 
operation the elements of the second line of the table according to Figure 3 c are each 
EXORed with random number R 2 = 10. The element in the second line and the first 
column of the table according to Figure 3d thus results from EXORing the element 
in the second line and first column of the table according to Figure 3 c with random 
number R 2 Z = 10. The further elements of the second line of the table according to 
Figure 3d are formed accordingly. The first line of the table according to Figure 3d 
is adopted by Figure 3c unchanged. 

With the table shown in Figure 3d one can determine likewise disguised output 
data from disguised input data. The thus determined disguised output data can be 
supplied to further operations for processing disguised data or one can determine 
plaintext data therefrom by EXORing with random number R 2 = 10. 

Use of the table shown in Figure 3d makes it possible to perform nonlinear op- 
erations with disguised secret data and protect said secret data from unauthorized 
access. The security-relevant operations themselves are still also protected from un- 



authorized access since differently disguised functions can be used at every execu- 
tion of the operations and the security-relevant operations themselves cannot be in- 
ferred even if the disguised functions could be determined. After conversion to 
plaintext, however, both the original security-relevant operations and the operations 
performed with the aid of disguised functions yield identical results. For example, 
input value 00 yields output value 01 according to the table in Figure 3 a. In order to 
check whether the disguised table shown in Figure 3d yields the same output value 
one must first EXOR input value 00 with random number Ri = 1 1 . As a result of 
said combination one obtains the value 11. According to the table from Figure 3d, 
input value 1 1 likewise yields output value 1 1. In order to determine the plaintext 
from said output value one must EXOR the output value with random number R 2 = 
10. As a result of said combination one obtains the value 01 which exactly matches 
the value determined with the aid of the table shown in Figure 3 a. 

Disguising the security-relevant operations or the input values can be effected 
not only by EXORing but also by other suitable types of combination, for example 
modular addition. Furthermore, the invention is not limited to the application of 
nonlinear functions represented by means of lookup tables. One can also use any 
nonlinear and even linear functions for which a suitable disguised function can be 
determined. 
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Patent claims 

L A data cairier having a semiconductor chip (5) with at least one memory con- 
taining an operating program which is able to execute at least one operation 
{h\ the execution of the operation (h) requiring input data (x) and the execution 
of the operation (h) generating output data characterized in that 
the operation (h) is disguised before its execution, 
the disguised operation (h R i) is executed with disguised input data 
(x ® R x \ and 

the disguising of the operation (h) and the input data (x) is coordinated 
such that the execution of the disguised operation (h R \) with disguised in- 
put data (j ® Ri) yields output data (y) identical with the output data (y) 
determined upon execution of the undisguised operation (h) with undis- 
guised input data (x). 

2. A data carrier according to claim 1, characterized in that at least one random 
number (R\) enters into the determination of the disguised operation (h R \) and 
the disguised input data (x ® Ri). 

3 . A data carrier according to either of the above claims, characterized in that the 
determination of the disguised operation (h R {) and the disguised input data 

(x ® Ri) is effected with the aid of EXOR operations. 

4. A data carrier according to any of the above claims, characterized in that the 
disguised operation (h R {) is permanently stored in the data carrier in advance. 

5. A data carrier according to claim 4, characterized in that at least two disguised 
operations (h RU h RV ) are permanently stored in the data carrier in advance and 
one of the stored disguised operations (h RU h Rr ) is selected randomly when a 
disguised operation is to be executed. 

6. A data carrier according to any of claims 1 to 3, characterized in that the dis- 
guised operation (h Ri ) is recalculated before its execution and the at least one 
random number (R\) is redetermined for said calculation. 



A data carrier according to any of the above claims, characterized in that the 
operation (h) is realized by a table stored in the data carrier which establishes 
an association between the input data (x) and the output data (y). 
A data carrier according to claim 7, characterized in that the disguising of the 
input data (x) contained in the table is effected by combination with the at least 
one random number 

A data carrier having a semiconductor chip (5) with at least one memory con- 
taining an operating program which is able to execute at least one operation 
(h\ the execution of the operation (h) requiring input data (x) and the execution 
of the operation (h) generating output data (y), characterized in that 
the operation (h) is disguised before its execution, 
the disguised operation (h Ri ) is executed with disguised input data 
(x®*i), 

the disguising of the operation (h) and the input data (x) is coordinated 
such that the execution of the disguised operation (/^l/a) with disguised 
input data (x ® R x ) yields output data (y ® R 2 ) which are disguised rela- 
tive to the output data (y) determined upon execution of the undisguised 
operation (h) with undisguised input data (x), and 

the undisguised output data (y) can be determined from the disguised out- 
put data (y ® R2) with the aid of data (R 2 ) used for disguising the opera- 
tion (h). 

A data carrier according to claim 9, characterized in that at least one random 
number (R{) enters into the determination of the disguised input data (x ® Ri) 
and at least two random numbers (R\, Ri) enter into the determination of the 
disguised operations {h mR2 ). 

A data carrier according to either of claims 9 and 10, characterized in that the 
determination of the disguised operation (hmicd ^ the disguised input data 
(x ® Ri) is effected with the aid of EXOR operations. 

A data carrier according to any of claims 9 to 11, characterized in that the dis- 
guised operation (h R \ R2 ) is permanently stored in the data carrier in advance. 
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13. A data carrier according to claim 12, characterized in that at least two dis- 
guised operations (h RlR2 , h RVB2 ) are permanently stored in the data carrier in 
advance and one of the stored disguised operations {h RXR2 , h RVR2 ) is selected 
randomly when a disguised operation is to be executed. 

14. A data carrier according to claim 13, characterized in that the random numbers 
(R h R 2 ) for determining the first disguised operation (h mR2 ) are inverse to the 
random numbers (Ri\ R 2 ) for determining the second disguised operation 
(^r/aO with respect to the combination used for determining the disguised 
operations (h Rva , h RVJ &). 

15. A data carrier according to any of claims 9 to 11, characterized in that the dis- 
guised operation (h Rim ) is recalculated before its execution and the random 
numbers Rz) are redetermined for said calculation. 

16. A data carrier according to any of claims 9 to 15, characterized in that the op- 
eration (h) is realized by a table stored in the data carrier which establishes an 
association between the input data (jc) and the output data (y). 

17. A data carrier according to claim 16, characterized in that the disguising of the 
input data (x) contained in the table is effected by combination with the at least 
one random number and the disguising of the output data (y) contained in 
the table is effected by combination with the at least one further random num- 
ber (i? 2 ). 

18. A data carrier according to any of the above claims, characterized in that the 
operation (h) is a nonlinear operation with respect to the combination used for 
disguising the operation (/?). 
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Abstract 

The invention relates to a data carrier having a semiconductor chip (5) with at 
least one memory. The memory contains an operating program that is able to per- 
form at least one operation (h). In order to prevent unauthorized access to the data 
(x) processed with the operation {h\ both said data and the operation (h) itself are 
disguised. The disguising of the data (x) and the operation (h) is coordinated such 
that the disguised operation (h Rm h RiR1 ) generates either the output data (y) of the 
undisguised operation (h) or disguised output data (y ® R 2 ) from which the output 
data (y) can be determined. 
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